GovernanceNewBlog / Insights
Strategic perspective on cyber risk
Analysis, research and lessons from the field.
GovernanceNew
Risk quantificationQuantifying cyber risk for the board
Likelihood and impact, price-moving exposure versus noise, and how to report it to the board.
NIS2NIS2 incident notification: building a process that holds up under pressure
The 24- and 72-hour deadlines aren’t the problem. Deciding them while the incident is already under way is.
GovernanceCyber risk appetite: why the board needs to put it in writing
Without a stated threshold, every security decision gets made from scratch — and justified after the fact.
Sell-sideSell-side readiness: preparing a target for cyber diligence
Evidence, documentation and reducing the surprises that move price.
NIS2NIS2 penalties and the personal liability of directors
The fine ceilings make headlines. The part that should worry a board more is different.
NIS2NIS2 and the supply chain: what to actually ask your suppliers
Article 21 explicitly includes supply-chain security. A questionnaire alone doesn’t demonstrate it.
GovernanceWhat the board should actually ask whoever leads security
A thirty-slide technical report is not oversight. A few right questions, asked regularly, are.
M&ACybersecurity in M&A: beyond the checklist
Why evidence-based due diligence changes deal outcomes.
InsightThe true cost of downtime (and how to measure it)
A pragmatic approach to understanding business impact beyond the obvious.
RegulatoryNIS2 for the board: what decision-makers need to know
Turning a directive into decisions the board can actually take.
GovernanceThe vCISO: when security leadership on retainer makes sense
Governance, risk-based priorities and board reporting, without a full-time hire.
ComplianceProportionate compliance: why ticking boxes does not protect you
Formal compliance and real risk are not the same thing. Evidence and measured exposure are where looking secure and being secure diverge.
IdentityIdentity and access: why IAM is the real perimeter
MFA, privileges, the access lifecycle and service accounts.
Digital ForensicsDigital evidence that holds up in court: acquisition, preservation, analysis
What it takes for technical evidence to stand before a judge.
IntegrationThe Day 1 plan in an acquisition
From close to controlled integration: access, monitoring and the controls that cannot wait.
CloudCloud security: the misconfigurations that matter most
Shared responsibility, IAM, secrets management and log visibility.
Due diligenceBuy-side cyber due diligence: beyond the questionnaire
Identifying material risks, validating controls and quantifying exposure to support valuation and price.
ArchitectureZero Trust in practice: beyond the slogan
Identity as the perimeter, segmentation and least privilege, in a sequenced path.
Incident ResponseThe first 60 minutes of an incident: what to do (and what not to do)
Containing the attack without destroying the evidence you will need later.
GovernanceFrom directive to board plan: decisions you can approve
Turning NIS2 and CRA into something a board can understand, approve and fund: gap assessment, costed roadmap, reporting.
RansomwareRansomware: pay or don’t pay is the wrong question
The decision is prepared months earlier, while you are not yet on fire.
DORADORA for the financial sector: digital operational resilience
Regulation (EU) 2022/2554 harmonises ICT risk management, incident reporting, resilience testing and oversight of critical providers.
Supply chainThird-party and supply-chain risk in M&A
OT vendors, critical dependencies and permanent access: mapping and monitoring what you inherit.
OT/ICSOT/ICS security: protecting without stopping the process
IT/OT convergence, segmentation and patching in systems you cannot switch off.
Incident ResponseThe incident response retainer: why preparation changes the outcome
A contract already signed, a plan already rehearsed, roles already assigned.
CRAThe Cyber Resilience Act explained: security in digital products
CE marking, security-by-design, vulnerability handling and reporting duties: what changes for makers of products with digital elements.
NIS2NIS2 in practice: who is in scope, what changes, how to prepare
Directive (EU) 2022/2555 widens the perimeter and puts accountability on management bodies. An operational reading, without alarmism.
BEC & FraudBusiness Email Compromise: the threat that uses no malware
No exploit, no virus — just trust and a weak payment process.
Case StudiesIndustrial Equipment Manufacturer
Third-party risk, brought under control ahead of a cross-border acquisition.
Case StudiesBuy-side cyber due diligence on a fintech target
Technical due diligence on a payments platform that surfaced material exposures, with a direct impact on price negotiation and a Day 1 remediation plan.
Case StudiesDORA readiness for a mid-sized financial institution
A DORA readiness programme that closed the main gaps in ICT risk management, incident reporting, and critical ICT providers, with an operational resilience testing cycle in place.
Case StudiesPre-transaction posture assessment of an insurance group
A security posture and third-party risk assessment ahead of a corporate transaction, distilled into a board-level roadmap with clear priorities and timelines.
Case StudiesSecurity governance (vCISO) for an asset management firm
A vCISO engagement that brought structure and risk-based priorities to an asset management firm, with board reporting that turns security into a business decision.
Case StudiesOT/ICS Security for an Industrial Manufacturer
IT/OT convergence secured and lines segmented — without ever stopping production.
Case StudiesIP and Brand Protection for a Luxury Maison
IP theft and counterfeiting contained across an extended, cross-border supply chain.
Case StudiesSupply-Chain Risk for a Manufacturing Group
Suppliers mapped and continuously monitored, bringing third-party risk under control.
Case StudiesResilience Testing and Incident Readiness for a Production Plant
Scenario exercises to test detection, response and business continuity before a real incident.
Case StudiesInternational Law Firm
Client confidentiality and legal privilege proven against a client-mandated audit, with targeted defence against phishing and BEC.
Case StudiesExpert Witness in a Commercial Dispute
Digital forensics and expert witness testimony supporting a party in a commercial dispute, with a court-defensible report.
Case StudiesPublic Body Operating an Essential Service
NIS2 compliance and operational continuity for an essential service, with a Zero Trust architecture and assurance demonstrable to the competent authority.
Case StudiesRansomware Response for an Omnichannel Retailer
Containment, preserved evidence and priority-led recovery after warehouse and point-of-sale systems were encrypted.
Case StudiesBusiness Email Compromise Fraud at a Services Firm
Investigation of a diverted payment, with payment-process controls and detection brought back into order.
Case StudiesIncident Readiness for an Always-On E-commerce
Playbook, retainer and contracted availability to withstand incidents during seasonal peaks.No articles in this category yet.
Cover images: Unsplash. Photographer credit is shown on each article.